4 ms·
They might be referring to a web application firewall: http://en.wikipedia.org/wiki/Application_firewall#Web_application_firewalls http://en.wikipedia.org/wiki/
by franck 15y ago
They might be referring to a web application firewall: http://en.wikipedia.org/wiki/Application_firewall#Web_application_firewalls http://en.wikipedia.org/wiki/Application_firewall#Web_applic...
- jojo1 15y agoWAFs are snake oil.
- kwantam 15y agoCould you expound upon this a bit please?
- jojo1 15y agoThey are the same kind of crap as personal firewalls are.
- deleted 15y ago[deleted]
- muppetman 15y agoI disagree. While not a magic "I've added that, now I'm totally secure" the one I have deployed stops many attacks designed to infect old code. I don't have that old code, but if I did the WAF would stop the attacts against it. Is it perfect? Of course not. Is it another layer of protection, sure it is.
- jojo1 15y agoSo, you disagree with me. That's perfectly fine. But why are you down voting me for not sharing your position? I've been working a long time in the "security industry". Believe me, it has reasons why I call products like WAFs snake oil...
- thehigherlife 15y agoI think it has a lot to do with making an incredulous statement without providing some evidence, or discussion as to why you think "WAFs are snake oil".
- wmf 15y agoOK, so actually state your reason. You're being downvoted because we can't read your mind.
- jojo1 15y agoOk, than go on. :-)
- Locke1689 15y agoWAFs are usually viewed as relatively useless as they waste time on dumb attacks (specifically blacklisting) that harms more than it helps. Only the stupidest attacks can be caught using WAFs and they are more likely to block legitimate traffic than to help with security. The idea is similar to using blacklists in filter functions in XSS or SQL protection mechanisms. In theory they could block all malicious but in practice they're poorly written and poorly configured crap that act as more security theatre than anything else. The proper approach is to use context-sensitive whitelists for all client input, not add on layers of what is essentially protocol grep.
- seanp2k 15y agoAnd do you really think that's a feasible expectation for the typical shared hosting client -- a business owner with little tech experience who doesn't have the money to hire an actual good developer? The person who doesn't even know that they don't know good developers from bad developers? >"The proper approach is to use context-sensitive whitelists for all client input, not add on layers of what is essentially protocol grep." It's regex for HTTP requests / responses. Literally, that's all it does. >"WAFs are usually viewed as relatively useless as they waste time on dumb attacks (specifically blacklisting) that harms more than it helps. " By who? References? As I mentioned above, we use WAFs and they help a lot with stupid attacks, because stupid attacks are what most of the attacks are; automated attack crap running on botnets to put up phishing pages on easy targets.